"App Store" matching MCP connectors:
GET /v1/connectors – MCP directory API referenceMatching Connector Tools:
Scan what a public site or AI-built app exposes. Returns a signed, exploitability-graded claim.
Security scanner for MCP servers and skills: Unicode injection, patterns, secrets.
Passive domain-perimeter checks — cert expiry, subdomain takeover, lookalikes — as agent tools
55 tools, 7 Resources, Sigma rules, email SPF/DMARC, MITRE, CVE/KEV, risk_score. No key.
Read-only agent-commerce audit, upgrade verification, diagnosis and x402 probing.
Triage a CVE: how severe it is, whether it is exploited, and how likely exploitation is.
Scan a deployed app URL for exposed keys, open Supabase tables and missing security headers.
WHOIS/RDAP, DNS, SSL, live subdomains with IPs, and SPF/DMARC/DKIM for any domain.
Check a live app you own for public databases, leaked keys and exposed files.
Scan, monitor and fix a live web app from your editor: graded security reports with fix prompts.
Scan a page for hidden prompt-injection payloads targeting AI agents.
Check dependencies against CISA's real Known Exploited Vulnerabilities feed.
Pay-per-call cybersecurity for AI agents: vuln scans, threat intel, compliance, code security.
Find known subdomains of a domain. Passive data; may include historic entries. List or count.
Scan any MCP server for tool-poisoning, security, auth & license. Trust score before install.
Scan the open TCP ports of your own public IP. Fast (32) or deep (65535). No key, no signup.
Find the right security-disclosure contact for any internet asset (domain, IP, package, repo, app).
Compliance & security scan for your app: secrets, exposed files, headers, privacy, AI-disclosure.
Security scanner for n8n workflows + live MCP Trust-Check. 18 rules, OWASP mapped. Paid x402 API.
CVE search, vulnerability database, EPSS exploit prediction, KEV, IP reputation & threat feed.